Solutions Who We Serve Insights & Events About Contact
Published on July 29, 2026 8 min read

Seven CUI Enclave Myths for CMMC Level 2 (GCC High)

internet security concept or cybersecurity, digital padlock, online security and data protection

Summary: An enclave can be the fastest and most cost-efficient route to CMMC Level 2, but the model is filled with assumptions. These are the seven myths we see most often, and how to confront them on your own terms before an assessor does it for you.

If you handle Controlled Unclassified Information (CUI), you have almost certainly been told that a Microsoft 365 GCC High enclave is the easy button for CMMC. It can be, if what you need is a home for collaboration functions like email, Teams, and SharePoint. Done right, a CUI enclave is a disciplined act of scoping: you decide exactly where CUI lives, wall it off inside a software-defined perimeter, and protect that smaller footprint to the full NIST SP 800-171 standards; cutting compliance costs and shrinking your audit scope to a fraction of your enterprise. For a contractor facing the prospect of hardening every laptop, server, and application in the business, that reduction in scope is often the difference between a program that is achievable and one that is not.

But “done right” is carrying a lot of weight in that sentence. The GCC High enclave is not a product you buy but a boundary you draw, and most failures trace back to a handful of misconceptions.

Below, we have compiled the common myths we see most often behind that “easy” button. Confronting them on your own terms, before an assessment, is far cheaper than having an assessor confront them for you. A failed assessment does not just cost the reassessment fee; it can cost the contract that required certification in the first place.

Myth 1: “An enclave makes us compliant.”

Even a correctly configured GCC High enclave does not satisfy all 110 controls and 320 assessment objectives for Level 2. Most solutions cover only a subset of controls. You still need documented policies and procedures, a risk assessment, a change management process, and an incident response plan. This is work the enclave vendor will not do for you; you have to treat the enclave as the beginning of a compliance program, not the end of one.

Myth 2: “CUI is in the enclave, so our endpoints are automatically out of scope.”

This is the assumption that quietly sinks assessments. Enclaves protect data inside the boundary well; contractors get hurt by everything that happens around it. The DoD’s own CMMC FAQ is precise here: an endpoint hosting a virtual desktop (VDI) client is out of scope only if it is configured so that nothing but keyboard, video, and mouse data ever reaches it; no local storage, no clipboard transfer, no drive mapping, no printing, and no screenshots. Miss any of those, and the endpoint becomes a CUI asset that pulls straight back into scope.

“Out of scope” is a configuration you must enforce and prove, not a status the enclave confers by default. This is where good intentions go wrong in practice: a user pastes a paragraph out of the enclave into a local email to “just get it to a colleague” or a sync client quietly caches a file to a laptop, and suddenly a device you excluded from your System Security Plan (SSP) is handling CUI.

Print CUI, handle paper CUI documents, or work with it on the shop floor, and the same logic applies.

Myth 3: “We can just pay a vendor and be done with it.”

There is no fully outsourced CUI boundary under CMMC, and no “CMMC in a box.” Some vendors claim you can drop your data into their enclave and walk away compliant; many cover only a sliver of what is required, while some are not accredited to provide the service at all. External service providers can carry real weight, but the governance, the policy, and the annual affirmation remain the responsibility of the contractor, signed by a senior official at your company who carries real accountability for it.

If a provider bills itself as a “one-stop shop” that makes compliance effortless, treat it as your cue to walk away. When CMMC prep is described as “turnkey,” controls are often implemented only at the superficial level, leaving gaps in logging and administrative oversight that an assessor will find.

Myth 4: “Encrypting CUI takes it out of scope.”

A popular workaround has been to encrypt CUI and park the ciphertext on systems that do not otherwise meet NIST SP 800-171 standards, reasoning that encrypted data is no longer actually CUI. The DoD has now explicitly rejected that idea.

CUI remains controlled until it is formally decontrolled; encrypting it, at rest or in transit, does not convert it into non-CUI, or let you treat the encrypted copy as out of scope. Encryption is a control you still owe, not a boundary that erases scope. If you built any part of your enclave on encryption-as-scoping, re-baseline your data flow diagrams now, because that interpretive shortcut is gone.

Myth 5: “Hosting and identity are just technical details.”

They are pass/fail conditions. Your cloud service provider must be FedRAMP Moderate authorized or meet DoD equivalency. If you miss that, it can mean an automatic failure.

With ITAR or other export control obligations, you must know where data resides and ensure only U.S. persons, including support staff, can touch it. Expect friction on the human side: an enclave stands up its own identity domain, so users typically carry two non-federated accounts, which is a training and support burden as much as a technical one.

Myth 6: “The enclave is always the right answer.”

A GCC High enclave is a carve-out and carve-outs only pay off when what you are walling off is small relative to the whole. If most of your revenue is defense work, isolating a “small” collaboration space can create more work than it saves as you keep expanding it. There is also risk in under-drawing the line: if you claim that only ten people touch CUI but it turns out to be twelve, and the extra two live outside the enclave, that is an automatic fail.

Sometimes the honest answer is to treat your enterprise itself as the CUI boundary. Watch scalability: a good architecture should let you add a contract, onboard a subcontractor, or stand up a CUI compute environment without redrawing the boundary every time. The math also shifts over time: an enclave that fits ten users comfortably can become an administrative drag at eighty, when you are running two parallel environments, two identity stacks, and two sets of patching, monitoring, and support.

Enclaves shine for new contracts but they rarely make migrating existing ones painless.

Myth 7: “Once we pass, we’re done.”

CMMC Phase 1 requires self-attestation, which comes with annual executive affirmations that those controls are still working. “Continuous” is not a figure of speech. It means around the clock, every day, and with the evidence to prove it.

The enclave you stand up this year needs to be governed, monitored, and maintained every year after. Configuration drift, staff turnover, and new data flows will steadily erode a boundary that no one is tending. Compliance is a posture you hold, not a milestone you pass.

The Common Thread

These myths trade a hard question for a comfortable assumption, and the antidote is the same in each case: map how CUI arrives, how it is handled, how it enters and leaves the enclave, and what it leaves behind. A boundary drawn without that map is just a guess, and assessors are adept at finding those guesses.

None of this is an argument against M365 GCC High enclaves but an argument for treating the enclave as compliance engineering rather than a purchase. A well-drawn CUI boundary for collaboration, paired with a shared responsibility matrix that assigns every one of the 320 objectives to a named owner and an organization that owns the governance no vendor can perform for it, is what turns the model’s promise into a passing assessment.

Get the boundary right, and the enclave becomes exactly what it should be: the most efficient path to protecting the data your contracts depend on.

Final Thoughts: Scope It Right the First Time

Securitybricks, powered by Aprio, builds properly configured CUI enclaves and a shared responsibility matrix that assigns every one of the 320 objectives to a named owner so nothing falls through the gap between you and your vendor. Contact our team today.

Book a CMMC scoping call:

Raj Raghavan leads CMMC and CUI enclave strategy at Aprio. This article is intended for general information purposes only and does not constitute legal or compliance advice.

How we can help

Aprio helps defense contractors scope, build, and maintain CMMC-ready environments, so you can account for every control, every objective, and every audit that stands between you and your next contract. Connect with us

internet security concept or cybersecurity, digital padlock, online security and data protection